DRAFT (revamp 2026-07) — for SA attorney review; not legal advice; not for publication.
This document is a working draft prepared for review by a qualified South African attorney before it is published or relied upon.
All statutory references in this draft are indicative and must be verified by counsel against the current text of each Act before any reliance or publication.
Several items require attorney completion and are marked [ATTORNEY-REQUIRED].
Missing or unconfirmed operational details are marked [TBD].
This Privacy Policy ("Policy") is the POPIA section 18 information notice for eRunna (Pty) Ltd ("eRunna", "we", "us", "our"). It applies to every person who interacts with our mobile applications, websites, runner and merchant onboarding portals, and any in-person data-collection activities such as mall activations (collectively, the "Services").
eRunna is an on-demand errand, delivery, and marketplace platform connecting customers, runners [ATTORNEY-REQUIRED: confirm the correct legal characterisation of runners' engagement status (e.g. independent contractor vs employee) under the Labour Relations Act, the Basic Conditions of Employment Act, and applicable case law before describing runners as "independent service providers" anywhere in the Services], merchants, and partners across South Africa. We operate from Johannesburg, Gauteng.
1. Responsible party (POPIA s18(1)(a))
- Name: eRunna (Pty) Ltd
- Registration number: [TBD: company registration number]
- Registered address: 1 Wedgewood Link Rd, Bryanston, Johannesburg, Gauteng, 2191 (by appointment only; no public walk-ins) [TBD: confirm the registered office address on incorporation — a provisional entity has no registered office until incorporation is finalised]
- Operator / development services: BIX Technology (provisional) — providing development and operational services on behalf of eRunna under a POPIA-compliant operator agreement [TBD: confirm operator DPA in place — see s20/s21]
- General contact: info@erunna.app | 010 140 6554
2. Information Officer (POPIA s18(1)(a); s55/s56 + Reg.4)
eRunna has designated an Information Officer as required by POPIA s55/s56 and the Information Regulator Regulations. The Information Officer is responsible for ensuring eRunna's compliance with POPIA, handling data-subject requests, and liaising with the Information Regulator of South Africa.
- Information Officer: [TBD: full name of registered Information Officer]
- Contact: [TBD: dedicated Information Officer email address, e.g. privacy@erunna.app]
- Registration status: [TBD: confirm registration on Information Regulator eServices portal before launch — mandatory under POPIA s55/s56 before duties begin]
For all data-subject requests (access, correction, deletion, objection), complaints, or privacy concerns, contact the Information Officer at the address above. You may also lodge a complaint directly with the Information Regulator of South Africa: www.inforegulator.org.za | inforeg@justice.gov.za.
3. Categories of personal information collected (POPIA s18(1)(b))
We collect the following categories of personal information, depending on your role and your use of the Services:
3.1 General personal information (all users)
- Identity and contact: full name, email address, mobile phone number, and (where provided) profile photo.
- Authentication: Firebase UID, session tokens, and device-binding identifiers.
- Location data: precise foreground GPS location for pickup/drop-off, routing, ETA, and nearby-service features; for runners only, precise background GPS location during an active delivery so customer-visible tracking can continue while the app is minimised.
- Device and technical data: device identifiers (IDFV, Android ID), operating system and version, app version, diagnostics, and crash logs.
- Order and errand data: pickup and drop-off addresses, item descriptions, order timestamps, and delivery history.
- User-supplied images: optional profile photos, KYC identity-document images and selfie/liveness captures, item/reference photos, chat image attachments, runner pickup/drop-off/receipt proof, and expense receipt images.
- Payment information: Paystack-issued payment tokens and authorisation codes. We do not store full card numbers, CVVs, or PINs. See the Subprocessors list for the Paystack data-processing relationship.
- Communications: support messages, in-app chat transcripts (where applicable), ratings, and reviews.
- Marketing and event data: name, email address, and mobile number collected via the "Join the waitlist" web form or at in-person events such as mall activations; marketing-consent status and opt-out records.
3.2 High-sensitivity information collected at KYC (runners / merchants)
During runner onboarding and identity verification (KYC), we collect high-sensitivity categories of personal information. Only biometric data is special personal information under POPIA section 26 (processed on a section 27 basis). The SA ID number and banking details are not section 26 special personal information — they are ordinary personal information of a high sensitivity, processed on a section 11 basis and secured under section 19. [ATTORNEY-REQUIRED: confirm the categorisation of the SA ID number and banking details, and the lawful basis for each.]
- South African identity number (SA ID): collected for identity verification, fraud prevention, and regulatory compliance. SA ID numbers carry a high sensitivity level and are treated accordingly under s19 security requirements.
-
Biometric data (selfie / liveness image): a facial image or liveness video captured via our KYC
verification process for identity-matching purposes. This constitutes biometric information under POPIA s1 and is
special personal information under s26.
Processing basis: your explicit, specific, and informed consent under POPIA s27(1)(a), given separately from your acceptance of the general Terms of Service at the point of KYC capture. You have the right to withdraw consent at any time, subject to the consequences described in section 10 below.
[ATTORNEY-REQUIRED: confirm whether s57 prior authorisation from the Information Regulator is required for biometric processing in this context before the KYC flow goes live.] - Banking details (runners and merchants): bank account number and branch code collected for payout processing. Processed under POPIA s11(1)(c) (contract) and s11(1)(a) (consent).
[ATTORNEY-REQUIRED: confirm the complete lawful basis for each special-PII category under s27(1)(a)–(h); confirm the KYC biometric-consent form wording meets the "explicit, specific, voluntary, informed, separate from blanket T&Cs" standard; confirm SA ID minimisation and retention limits.]
3.3 Collection points
- Mobile app signup (customer): identity, contact, location, payment, and device data.
- Runner onboarding portal: identity, contact, SA ID, biometric KYC selfie, banking details, vehicle/transport details, and location.
- Merchant portal: business identity, contact, banking details, and product/inventory data.
- Partner (affiliate) portal: identity, contact, and banking details.
- "Join the waitlist" web form: name, email address, and/or mobile number; marketing-consent preference.
- In-person mall activations and events: name, email address, and/or mobile number collected on paper forms or digitally; a POPIA s18 collection notice is provided at the point of collection and marketing consent is obtained separately (see section 8).
- Support interactions: communications and any personal information you voluntarily share.
4. Purposes of processing (POPIA s18(1)(c))
- Service delivery: matching customers with runners; routing, tracking, and delivery ETA; order fulfilment; marketplace listings; notifications.
- Payments: processing payment authorisations, handling refunds and cancellations, routing payouts to runners and merchants.
- Identity verification and fraud prevention: runner KYC (SA ID + biometric match), fraud detection, abuse investigation, and platform-integrity monitoring.
- Safety: incident investigation, emergency-contact use, runner and customer safety features.
- Customer support and communications: responding to support requests, resolving disputes, in-app messaging.
- Analytics and service improvement: aggregated or de-identified performance monitoring, product improvement, and research.
- FICA / AML-CFT compliance (customer due diligence): where eRunna constitutes an accountable institution under the Financial Intelligence Centre Act 38 of 2001 (FICA), we process personal information for customer due diligence (CDD) obligations, record-keeping [ATTORNEY-REQUIRED: confirm citation — confirm the exact statutory record-keeping period under FICA before stating a fixed number of years], and suspicious-transaction reporting to the Financial Intelligence Centre. [ATTORNEY-REQUIRED: confirm whether eRunna falls within an "accountable institution" category under FICA Schedule 1 in respect of any of its payment or marketplace activities, and the precise CDD obligations that follow.]
- Legal compliance and regulatory reporting: tax obligations, court orders, regulatory submissions, and enforcement of our Terms of Service.
- Direct marketing: where you have given consent under POPIA s69, or where the existing-customer exemption applies, we may send you information about our Services, promotions, and updates. See section 8.
- Waitlist and event follow-up: contacting persons who have expressed interest via the "Join the waitlist" form or at in-person events, subject to the consent given at collection.
5. Lawful bases for processing (POPIA conditions — s11; s26/s27)
- Contract (s11(1)(c)): processing necessary to deliver the Services you have requested — errand matching, routing, payments, payout.
- Consent (s11(1)(a)): push notifications; background location (you can withdraw in device settings, which may limit functionality); biometric KYC selfie (explicit and separate consent — see s3.2); direct marketing (where the existing-customer exemption does not apply — see s8).
- Legal obligation (s11(1)(b)): tax and financial record-keeping; FICA customer due diligence and suspicious-transaction reporting; regulatory disclosures.
- Legitimate interest (s11(1)(f)): fraud prevention, platform safety, abuse detection, service-improvement analytics (where proportionate and not overridden by your rights). [ATTORNEY-REQUIRED: attorney to review each legitimate-interest reliance against the POPIA balancing test.]
For special personal information (SA ID number, biometric selfie, banking data — see s3.2), the primary basis is your explicit and specific consent under s27(1)(a), obtained separately from the general Terms of Service at the point of KYC capture, with the right to withdraw as described in section 10.
6. Recipients and sharing of personal information (POPIA s18(1)(d))
-
Subprocessors / operators (s20/s21): we share personal information with the following categories of service providers who process data on our behalf under written operator agreements:
- Cloud infrastructure and database: Google Cloud Platform (GCP) and Firebase — see section 7 for cross-border note.
- Payments: Paystack (South Africa) — payment processing, tokenisation, and payout services.
- Identity verification / KYC: [TBD: name of biometric/KYC verification provider]
- Messaging and notifications: [TBD: email and SMS provider(s)]
- Crash reporting and monitoring: Google Firebase Crashlytics.
- For a complete and current list, see the Subprocessors list.
- Service fulfilment (in-context sharing): limited personal information (first name, pickup/drop-off area, order status) is shared between customers, runners, and merchants strictly to the extent necessary to fulfil a specific errand or order.
- Merchants and partners (independent responsible parties): where you interact with a merchant or partner on the platform, that merchant or partner may independently process your personal information as a responsible party in their own right. [ATTORNEY-REQUIRED: attorney to confirm the responsible-party-vs-operator framing between eRunna, merchants, and partners — this is likely not a simple operator relationship.]
- Legal and safety disclosures: we may disclose personal information where required by law, court order, or to protect the rights, safety, or property of eRunna, our users, or the public.
- Business transfers: in connection with a merger, acquisition, restructuring, or sale of assets, personal information may be transferred to a successor entity, subject to equivalent privacy protections.
- We do not sell personal information to third parties for their own marketing purposes.
7. Cross-border transfers (POPIA s72)
POPIA s72 restricts the transfer of personal information outside South Africa unless certain conditions are met, including that the recipient country or organisation provides an adequate level of protection substantially equivalent to POPIA, or that data subjects have consented to the transfer.
- Google Cloud Platform / Firebase: GCP infrastructure may process data in regions outside South Africa. [TBD: confirm the GCP region(s) in which eRunna data is stored and processed — e.g. africa-south1 (Johannesburg) as primary, and whether any GCP services (e.g. Firebase Authentication, Cloud Functions) process data in non-ZA regions; confirm a POPIA-compliant DPA is in place with Google.]
- Paystack: Paystack may process payment data in Nigeria and/or other jurisdictions. [TBD: confirm Paystack data-residency and obtain/confirm a POPIA-compliant DPA or equivalent safeguard under s72.]
- Other subprocessors: [TBD: confirm data residency and DPA status for all subprocessors listed in the Subprocessors doc.]
Where transfers occur to countries that have not been assessed as providing adequate protection, we rely on contractual safeguards (standard data-protection clauses or equivalent), and we will disclose the specific safeguard applicable to each transfer in the Subprocessors list.
[ATTORNEY-REQUIRED: attorney to review each cross-border transfer against s72(1)(a)–(e) and confirm adequate safeguards; obtain/review POPIA-compliant DPAs with GCP and Paystack before launch.]
8. Direct marketing (POPIA s69)
We may send you direct marketing communications (email, SMS, push notification, or in-app message) about our Services, offers, and updates in the following circumstances:
- Consent: where you have expressly opted in to receive marketing communications from eRunna — for example, by ticking the marketing-consent checkbox on the "Join the waitlist" form or at a mall activation event.
- Existing-customer exemption (POPIA s69(3)(b)): we may contact existing customers about our own similar products and services, provided you were given a reasonable opportunity to opt out at the time of collection and at each subsequent communication. [ATTORNEY-REQUIRED: attorney to confirm the scope and limits of the existing-customer exemption in the context of eRunna's multi-persona model, and the application of any current Information Regulator direct-marketing guidance (confirm the exact title and date of the applicable guidance note).]
Opt-out / withdrawal: you may withdraw marketing consent or object to direct marketing at any time by clicking the "unsubscribe" link in any marketing email, replying "STOP" to any SMS, adjusting notification settings in the app, or contacting us at [TBD: Information Officer contact]. Withdrawal does not affect the lawfulness of processing before withdrawal. We maintain a suppression list and will honour opt-outs within a reasonable period.
8.1 "Join the waitlist" web form
If you submit your contact details via the "Join the waitlist" form on our website:
- We collect your name, email address, and/or mobile number for the purpose of notifying you when the Services become available in your area.
- You will be asked to tick a separate marketing-consent checkbox if you wish to receive broader product updates and promotional communications. Ticking that checkbox is voluntary and not a condition of joining the waitlist.
- You may withdraw from the waitlist or withdraw marketing consent at any time by contacting us at [TBD: Information Officer contact].
- We will retain waitlist data until we notify you of availability or until you request deletion, whichever is earlier. See the Data Retention Policy for details.
8.2 In-person mall activations and events
Where we collect personal information in person (for example at a shopping-centre activation):
- A POPIA s18 collection notice (this Policy or a summarised notice) is made available at the point of collection.
- Marketing consent is sought separately and is voluntary — participation in the activity or receipt of a promotional item is not conditional on giving marketing consent.
- [ATTORNEY-REQUIRED: if any in-person activity involves a competition, prize draw, or promotional giveaway, attorney to confirm compliance with the Consumer Protection Act promotional-competition rules (confirm the applicable section reference), including any prohibition on requiring a purchase and the disclosure requirements.]
- Paper forms and digitally captured data from events are transferred to our systems and subject to the same security and retention obligations as digital data.
9. Age policy — 18+ only (POPIA s34/s35)
The Services are intended for persons aged 18 years and older. We do not knowingly collect personal information from children under the age of 18.
POPIA s34 and s35 impose heightened obligations when processing the personal information of children, including a general prohibition on processing children's personal information without prior authorisation from the Information Regulator (s35(1)) unless a specific exception applies. We take this seriously given our marketing reach on platforms such as TikTok.
If you are under 18, you may not use the Services. If we become aware that we have collected personal information from a person under 18, we will delete it promptly. If you believe we have inadvertently collected such information, please notify us at [TBD: Information Officer contact].
[ATTORNEY-REQUIRED: attorney to confirm the applicable children's data protections under s34/s35 in the context of eRunna's TikTok reach and the waitlist web form, and whether any s57 prior-authorisation exposure exists for marketing to potentially under-18 audiences.]
10. Your rights as a data subject (POPIA s5; s18(1)(e)–(h))
Subject to POPIA and applicable law, you have the following rights in respect of your personal information:
- Right to be notified (s18): to be informed when your personal information is collected — this Policy serves as that notice.
- Right of access (s23): to request confirmation of whether we hold your personal information, and to access a copy of it.
- Right to rectification (s24): to request correction of inaccurate, outdated, or incomplete personal information.
- Right to erasure / destruction (s24(1)(c)): to request deletion or destruction of your personal information where we no longer have a lawful basis to retain it, subject to legal-retention obligations (including FICA record-keeping).
- Right to object (s11(3)): to object to the processing of your personal information on grounds of legitimate interest; to object to direct marketing at any time (s69(3)(a)).
- Right to withdraw consent (s11(1)(a)): where processing is based on consent, to withdraw that consent at any time without detriment (withdrawal does not affect prior lawful processing; certain functionality may become unavailable).
- Right to complain (s74): to lodge a complaint with the Information Regulator of South Africa if you believe your rights have been infringed.
To exercise any of these rights, submit a written request to the Information Officer at [TBD: Information Officer contact]. We will acknowledge promptly and respond within the period required by POPIA and its Regulations [ATTORNEY-REQUIRED: confirm citation — confirm the acknowledgement and full-response timelines (and any permissible extension) prescribed by POPIA / the Information Regulator Regulations before stating fixed day-counts]. We may require proof of identity before processing a request.
11. Retention (POPIA s14; s18(1)(d))
We retain personal information for no longer than is necessary to fulfil the purpose for which it was collected, or as required by law. Key retention periods include:
- Account and order data: retained while your account is active and for a period thereafter — see the Data Retention Policy for specific periods.
- FICA / AML-CFT records: retained from the date of the transaction or the end of the business relationship for the statutory period required by FICA [ATTORNEY-REQUIRED: confirm citation — confirm the precise FICA retention period before stating a fixed number of years, and the applicable accountable-institution category].
- KYC / biometric data (runners): retained for the duration of the runner relationship and for a post-termination period as required by FICA and applicable law; biometric data is deleted when no longer required for the stated purpose. [ATTORNEY-REQUIRED: confirm the maximum permissible retention period for biometric data and whether s57 prior authorisation affects this.]
- Marketing and waitlist data: retained until you withdraw consent, opt out, or request deletion — whichever occurs first.
- Tax and financial records: as required under the Income Tax Act and related legislation [ATTORNEY-REQUIRED: confirm citation — confirm the applicable tax record-retention period before stating a fixed number of years].
For full details, see the Data Retention Policy.
12. Security (POPIA s19)
We implement appropriate technical and organisational measures to protect personal information against loss, damage, unauthorised access, disclosure, and processing, including:
- Encryption of data in transit (TLS) and at rest where applicable.
- Role-based access controls and least-privilege access for internal systems.
- Continuous monitoring and anomaly detection.
- Operator agreements with all subprocessors (s20/s21) requiring equivalent security standards.
No method of transmission or storage is 100% secure. In the event of a security compromise that affects your personal information, we will notify the Information Regulator and affected data subjects as required by POPIA s22. Our internal breach-response procedure is maintained separately.
13. Automated decision-making (POPIA s71)
Our runner-matching and dispatch algorithms make automated decisions that may affect which runners are offered errands and at what priority. You have the right under POPIA s71 to request human review of any automated decision that has a significant effect on you. Contact us at [TBD: Information Officer contact] to exercise this right.
14. PAIA manual
eRunna is required to compile and publish a manual in terms of the Promotion of Access to Information Act 2 of 2000 (PAIA) s51. The exemption for small private bodies has lapsed [ATTORNEY-REQUIRED: confirm citation — verify the exact expiry date of the small-private-body PAIA-manual exemption and that no current exemption applies to eRunna] — on current understanding no exemption applies. [TBD: the PAIA manual will be published at this location before launch. Until it is available, submit information-access requests to the Information Officer at [TBD: Information Officer contact].]
15. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, the Services, or applicable law. Where changes are material, we will post an updated "Last updated" date and, where feasible, provide notice via email or in-app notification. Continued use of the Services after the effective date constitutes acceptance of the updated Policy, to the extent permitted by law. For material changes affecting your rights, we will seek fresh consent where required by POPIA.
16. Related policies
- Data Retention Policy — specific retention periods for each data category.
- Subprocessors list — current list of operators and cross-border transfer safeguards.
- Background Location Disclosure — prominent disclosure for background location processing (store/platform policy compliance).
- Security Incident Response — our POPIA s22 breach-notification procedure.
- Terms of Service — the agreement governing use of the Services.
- Refunds & Payments Policy — cancellation and refund terms.
- [TBD: PAIA Manual — to be published before launch.]